Installation

Moving from Search Head pooling to Search Head clustering -- replicating dashboards, saved searches, etc.?

alekksi
Communicator

Hi all,

We're in the process of migrating from pooling to clustering on our search heads. This is still in a testing phase so both are running side-by-side at the moment. The obvious change is that we are no longer using the mounted NFS pool (/splunk_pool) and are instead using local config which is replicated across.
Is there an easy way to migrate all of this data across? For example, we have upwards of 30 dashboards in the pool, yet obviously none of them are in the clustered setup. I can copy these manually across from /splunk_pool/etc/apps/search/local/data/ui/views and put them in /opt/splunk/etc/apps/search/local/data/ui/views/, but I would have to do this manually across all of the clustered nodes. Is there a way that this can be done automagically? I am also worried I will lose individual users saved searches and manual extractions.

Any help would be greatly appreciated!

Best regards,
Alex

Labels (1)
0 Karma

rphillips_splk
Splunk Employee
Splunk Employee

You would want to use the deployer to migrate your custom app configurations and private user configurations.

http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromsearchheadpooling

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...